Software Security Engineer, Infra & DevOps team Annapurna
Amazon Haifa, Haifa District, Israel
Software Development · 10,001+ employees
About the role
You will threat model new silicon and firmware architectures while conducting low-level penetration testing on privileged interfaces. Additionally, you will develop fuzzing and analysis tooling to ensure security across firmware and hardware components.
What they look for
Requirements
Candidates must have at least 4 years of low-level systems security research and vulnerability testing experience. Proficiency in C, ARM assembly, and deep knowledge of hardware security and cryptographic implementations are required.
Full description
The Annapurna Labs Security Team secures the firmware at the foundation of AWS custom silicon. We work on Graviton processors and the Nitro System — hardware that runs a substantial share of the world's cloud workloads — in close collaboration with the silicon architects and firmware developers who design it. Our engineers operate at the lowest levels of the stack: secure boot chains, hardware root of trust, attestation, cryptographic protocol design, and the boundaries between trust domains within the system.
Key job responsibilities As a Security Engineer, you will threat model new silicon and firmware architectures, conduct low-level penetration testing against privileged and externally reachable interfaces, review designs and code across multiple firmware components, and build the fuzzing and analysis tooling that makes this work repeatable at silicon scale. You will also help raise the security bar across the wider organization through direct engagement with firmware and hardware teams. We are looking for engineers fluent in C and ARM assembly, with real depth in secure boot, applied cryptography, or embedded exploitation, and the technical credibility to hold a position in a room full of people who designed the system you are testing.
Basic Qualifications: - 4+ years of low-level systems security research and vulnerability testing experience - Experience developing security tools (fuzzers, scanners, analysis frameworks) - Security architecture design and threat modeling experience - Proficiency in C and experience with Python - Deep knowledge of security aspects of ARM/x86 processor architectures - Strong understanding of hardware security (secure boot, cryptographic implementations, side-channel attacks) - Knowledge of security protocols and cryptographic primitives - Experience in AI usage for security research - Technical English proficiency
Preferred Qualifications: - Background in firmware reverse engineering and vulnerability research - Experience with fuzzing frameworks (AFL++, libFuzzer, Syzkaller) - Knowledge of virtualization security or hypervisor technologies - Familiarity with AWS services - Technical leadership, mentoring, and cross-functional collaboration - Security publications (research, CVEs) - CTF, bug bounty, or competitive security research background
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Similar roles
-
DevOps Engineer Intern — Summer 2027
Gallup Omaha, Nebraska, United States · $52K–$62K/yr
-
Ingénieur de production & DevOps H/F
Consort Group Lyon, Auvergne-Rhône-Alpes, France · €39K–€55K/yr
-
Azure DevOps Consultant
Alithya Ontario, Canada · CA$80K–CA$120K/yr
-
DevOps / Platform & Automation Engineer (m/w/d)
Bewerbung – TASKOM Dusseldorf, North Rhine-Westphalia, Germany
-
Configuration (DevOps) Engineer
Veeam Software Warsaw, Masovian Voivodeship, Poland
-
Specialist DevOps Engineer, CX
NICE pune, Maharashtra, India